Governing AI you did not build
Notes on running AI agents inside companies that will never standardize on one platform. Written for whoever is accountable the day an agent does something nobody approved.

Every AI governance product assumes your company will eventually pick one platform and route everything through it. That assumption is structurally wrong, and it is why the agents that most need governing are the ones that will never move.
Read
Almost everything sold as AI agent security is a camera. Cameras are genuinely useful and they have never stopped anything. Here is what the other two objects are, why vendors collapse all three into the word "control", and the test that tells them apart in a demo.

We set out to build a workspace where AI agents do real work alongside a team. The hard part was never making them capable. It was that the moment an agent holds a real credential on a real system, nobody in the company can answer three very ordinary questions about it.


